1207 vulnerabilidades · Database Orden: CVSS EPSS Año ID
CVE-2020-23833
Software Genérico Web Database
N/A
UNKNOWN
EPSS
6.1%
2020 1 PoC

Projectworlds House Rental v1.0 suffers from an unauthenticated SQL Injection vulnerability, allowing remote attackers to execute arbitrary code on the hosting webserver via a malicious index.php POST request.

CVE-2020-5726
Grandstream UCM6200 series Database
N/A
UNKNOWN
EPSS
6.4%
2020 CWE-89 2 PoCs

The Grandstream UCM6200 series before 1.0.20.22 is vulnerable to an SQL injection via the CTI server on port 8888. A remote unauthenticated attacker can invoke the challenge action with a crafted username and discover user passwords.

CVE-2020-10804
Software Genérico Web Database
N/A
UNKNOWN
EPSS
2.4%
2020 1 PoC

In phpMyAdmin 4.x before 4.9.5 and 5.x before 5.0.2, a SQL injection vulnerability was found in retrieval of the current username (in libraries/classes/Server/Privileges.php and libraries/classes/UserPassword.php). A malicious user with access to the server could create a crafted username, and then trick the victim into performing specific actions with that user account (such as editing its privileges).

CVE-2020-28172
Software Genérico Web Database
N/A
UNKNOWN
EPSS
4.2%
2020 2 PoCs

A SQL injection vulnerability in Simple College Website 1.0 allows remote unauthenticated attackers to bypass the admin authentication mechanism in college_website/admin/ajax.php?action=login, thus gaining access to the website administrative panel.

CVE-2020-5307
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
80.5%
2020 1 PoC

PHPGurukul Dairy Farm Shop Management System 1.0 is vulnerable to SQL injection, as demonstrated by the username parameter in index.php, the category and CategoryCode parameters in add-category.php, the CompanyName parameter in add-company.php, and the ProductName and ProductPrice parameters in add-product.php.

CVE-2020-15927
Software Genérico Database
N/A
UNKNOWN
EPSS
1.3%
2020 1 PoC

Zoho ManageEngine Applications Manager version 14740 and prior allows an authenticated SQL Injection via a crafted jsp request in the SAP module.

CVE-2020-15468
Software Genérico Web Database
N/A
UNKNOWN
EPSS
1.1%
2020 1 PoC

Persian VIP Download Script 1.0 allows SQL Injection via the cart_edit.php active parameter.